LENOVO BIOS AUTO-PATCHER for Supervisor Password Removal

Collapse
X
 
  • Time
  • Show
Clear All
new posts

  • CesrDroid
    replied
    Originally posted by Maxpower3

    serial number, type etc ... respect rules please
    Model: ThinkPad T480
    Serial Number: PF-1NSAAJ
    Motherboard Model: ET480 NM-B501 - rEV. 1,0 - 2018-03.03

    Issue:
    I am unable to remove the BIOS supervisor password. I have tried all recommended procedures, including the Lenovo Auto‑Patcher, but I am still locked out.

    What I have tried:

    Used Flashrom and a CH341A SPI programmer to read and write the BIOS chip.

    Worked from both Ubuntu and Windows 11 operating systems during the process.

    Flashed both 8MB and 4MB dumps (attached below).

    Ran the latest Lenovo Auto-Patcher script on my BIOS dumps.

    Flashed the patched BIOS back to the chip.

    I also tried the original BIOS dump for recovery.

    Current symptoms:

    With patched BIOS: The laptop does not boot and emits a continuous siren/alarm sound.

    With original BIOS: The laptop boots but asks for the supervisor password (which I do not have).


    Additional info:

    The board label says MN-B501.


    Thank you in advance for your help! Any guidance or clean/unlocked BIOS would be greatly appreciated.

    Leave a comment:


  • Maxpower3
    replied
    Originally posted by Polar Bear

    Method #1: Lenovo autopatcher

    Method #2: Supervisor password decryption

    Method #3: JLPC ADC shorting to GND

    method 1 should work
    Method 2 doesn't work. Password is in EC. Can't decrypt. It's not registered in the BIOS.
    Method 3: You must use a USB keyboard because the shunt disables the keyboard. Watch the other videos to understand, the timing of the shunt is important
    f1 is pressed before the shunt.






    Attached Files
    Last edited by Maxpower3; 07-01-2025, 08:54 AM.

    Leave a comment:


  • Maxpower3
    replied
    Originally posted by CesrDroid


    I just saw that I uploaded the file, but it's 6MB. The original BIOS is 16MB, but when I run the autopatcher, it doesn't work and the siren is activated.
    serial number, type etc ... respect rules please

    Leave a comment:


  • peste
    commented on 's reply
    post merged...next time look for a thread with the name and model, motherboard model of the laptop, and post there, if you can't find it, then make a new thread..

  • CesrDroid
    replied
    Originally posted by CesrDroid
    Can someone help me? When I use the autopatcher, the computer starts beeping and does not start the BIOS.

    I just saw that I uploaded the file, but it's 6MB. The original BIOS is 16MB, but when I run the autopatcher, it doesn't work and the siren is activated.
    Attached Files

    Leave a comment:


  • Polar Bear
    replied
    Originally posted by Vincehu
    Just bought a CH341A programmer for Thinkpad T480s, IC chip is 25Q128JVSQ,

    I used the AsProgrammer 2.1.0 .13 Version, But I cannot find this chip model in CH341A chip list, there are only 25Q128BV and 25Q128FV.
    Can someone help how to handle this IC 25Q128JVSQ?

    Thanks very much.
    Hi,

    you can use any of 25Q128BV or 25Q128FV they share same chip ID as your IC 25Q128JVSQ (see page 21).

    Or you can add your chip into list of supported chips yourself. Just edit file chiplist.xml,

    find line

    Code:
    <W25Q128FV id="EF4018" page="256" size="16777216"/>
    add after it

    Code:
    <W25Q128JV id="EF4018" page="256" size="16777216"/>
    save the file.

    Now try identify chip in AsProgrammer and you will see your chip in the list.

    Note: you can download more recent AsProgrammer 3.7 or AsProgrammer 2.1.2

    Polar Bear

    Leave a comment:


  • Polar Bear
    replied
    Hello Knucklegrumble,

    per your suggestion I would like to report unsuccessful case with Lenovo T480s. I followed your procedure and everything was going according plan except that after restoring original BIOS and reboot laptop asks for a password.

    I've made a post for my case with a details. I would appreciate if you take a look at it.

    Thank you for your work and help

    Polar Bear

    Leave a comment:


  • abrnb
    replied
    Hi,
    when i try to autopatch a file the fill generated and immediately deleted, pls assist me for this problem, Thanks

    Leave a comment:


  • Polar Bear
    replied
    Hello,

    A friend of mine approached me with request for help to recover access to a few electronic devices left after tragic death of his son. One of the devices is a Lenovo T480s laptop with UEFI Supervisor laptop. I did my research on internet for possible methods and couple of them lead to BadCaps forum.

    Laptop: Lenovo T480s
    MB: ET481 NS-B471 Rev: 1.0 2017-10-30
    Type: 20L7-002CUS
    S/N: PC-0WWFM7 18/08
    BIOS IC: 25Q128JVSQ

    Method #1: Lenovo autopatcher
    Video: https://www.youtube.com/watch?v=s9XlN2Hl0ag
    lenovo_autopatcher_0.2
    The BIOS has been read and stored 3 times in a files, CRC is the same for each file. The BIOS was processed by lenovo_autopatcher_0.2 successfully. The result bin file was written into the BIOS chip. At next laptop's boot a procedure to disable TPM was completed successfully. Then original BIOS was written/restored into BIOS chip. Following boot of the laptop still asks for password input.

    The procedure was completed/repeated a few times (with connected/disconnected batteries) with exactly same result.

    Method #2: Supervisor password decryption
    Video: https://www.youtube.com/watch?v=IhRw7ePhLKs
    Followed the video in attempt to decript Supervisor's password. Using UEFItool was found padding value (00700000h) and BIOS file was scanned for an offset (0003FC20h). Looking at 0073FC20h in BIOS file the password has 168 bites and bytes values way beyond keyboard scan codes. It is considered that this attempt/method is not applicable to Lenovo T480s.

    Keyboard scancodes: https://aeb.win.tue.nl/linux/kbd/scancodes-1.html

    Method #3: JLPC ADC shorting to GND
    Video: https://www.youtube.com/watch?v=D-PFVJpBcTY
    URL: https://www.badcaps.net/forum/troubl...-ec-pwd-bypass

    Followed the video, in many attepts to GND any pin 4,6,8,10 (ADC0:3) on JLPC pads and only once I was offered to press F1 go get into BIOS settings, for some unexplicable reason keyboard refused to respond on key presses. All following attempts was unsuccessful so far (to catch a right timing to corrupt data exchange and get into BIOS settings).

    Please suggest how Supervisor password can be remove.
    Your help is greatly appreciated.
    Attached Files
    Last edited by Polar Bear; 06-30-2025, 07:23 PM.

    Leave a comment:


  • volinakis
    replied
    Originally posted by Maxpower3
    The conclusion of his research for this thesis is :

    that he doesn't do anything well, and yet, it works.



    when he will discover your method he will realize he waste his time researching and writing his thesis. Imagine: after reading his thesis in front of colleagues and professors, the dumb of the class rises 2 fingers and says: I know a faster and better way!
    On a serious note, I bet you didn't discover your method by accident, you searched a way to interrupt communication between UEFI and EC and you found it.
    Last edited by volinakis; 06-30-2025, 02:33 AM.

    Leave a comment:


  • Maxpower3
    replied
    Originally posted by volinakis

    now we wait from him to document your method of bypassing SVP
    The conclusion of his research for this thesis is :

    that he doesn't do anything well, and yet, it works.




    Leave a comment:


  • volinakis
    replied
    Originally posted by Maxpower3
    impressive, well done, great job
    now we wait from him to document your method of bypassing SVP. I think in 2028!

    Leave a comment:


  • Maxpower3
    replied
    impressive, well done, great job
    Attached Files

    Leave a comment:


  • SVTV
    replied
    Originally posted by Maxpower3

    EC MEC1503 no solution
    Only programmer

    Leave a comment:


  • ali0robot
    replied
    Originally posted by Maxpower3

    AMD or Intel ?? intel not work
    L14 L15 complicated model
    look at the other posts in
    https://www.badcaps.net/forum/troubl...-ec-pwd-bypass


    it's intel, ok I will try second solution. thank you

    Leave a comment:


  • Maxpower3
    replied
    Originally posted by ali0robot
    Hi Maxpower3
    I have Lenovo L15 with part number GL4A0/GL5A0 NM-C631 and I followed your guidance for NPCE68APA0DX by make a short connection pin 1 or 128 with ground for two second when I can see Lenovo logo but problem is that laptop stuck in Lenovo logo. what am I doing wrong?
    AMD or Intel ?? intel not work
    L14 L15 complicated model
    look at the other posts in
    https://www.badcaps.net/forum/troubl...-ec-pwd-bypass



    Leave a comment:


  • ali0robot
    replied
    Hi Maxpower3
    I have Lenovo L15 with part number GL4A0/GL5A0 NM-C631 and I followed your guidance for NPCE68APA0DX by make a short connection pin 1 or 128 with ground for two second when I can see Lenovo logo but problem is that laptop stuck in Lenovo logo. what am I doing wrong?

    Leave a comment:


  • sonsuzbilgisayar
    replied
    Originally posted by gandi69
    Hi have a lenovo e595 with a supervisor password lock. I have tried the auto patcher from bios dump but my bios comes out to 32mb not 16 and wont fit on the flash.

    can anyone help?

    Laptop serial number is PF-2233EX

    type : 20NF-0006UK

    This system does not work for 32Mbytes. This system is only valid for 16MB. I have done it many times.​

    Leave a comment:


  • Maxpower3
    replied
    Originally posted by nguyenhuuducntu

    I'm sorry. This my model and original bios
    Serial Number R9-10W8WV
    Type Number 20UN-0001JP
    EC MEC1503 no solution

    Leave a comment:


  • nguyenhuuducntu
    replied
    Originally posted by SMDFlea

    Type the laptop serial number, full name and model, motherboard model, etc.
    post the contents of the original bios chip even if it is corrupted..

    read the forum rules..https://www.badcaps.net/forum/troubl...before-posting
    I'm sorry. This my model and original bios
    Serial Number R9-10W8WV
    Type Number 20UN-0001JP
    Attached Files

    Leave a comment:

Related Topics

Collapse

  • Vesko356
    [Guide] How to find the right HP bios version to flash
    by Vesko356
    First of all thanks to all of our members who have posted previously all methods posted here.
    Please leave a comment if you find something new,or have anything else to add.
    -----------------------------------------------------------------------------------------

    Find by serial number,model number or series

    If you know the laptop serial or model number go to HP support https://support.hp.com/us-en/drivers/laptops .
    Enter the serial number or model number and click submit.On the next screen you will have to enter the OS
    Operating system and OS version.If...
    08-11-2023, 03:27 AM
  • jbonavita
    ASUS TP500LA BIOS request/repair/merge?
    by jbonavita
    Hi, my laptop wont boot at all
    With original bios no POST, only LED lights
    With alternative BIOS from model TP500LN (flashed via programmer) the notebook works again
    Some issues
    A- with bios from 500LN, it won't update from bios of model 500LA (from 500LN v203 to 500LA v300)
    B- If updated from 500LN version 203 to 300, the battery stops being recognized

    Things I tried

    1- Update / clear ME: Took the non working bios, made a backup, and did this: https://www.badcaps.net/forum/troubl...theory/trouble...
    04-29-2025, 09:38 PM
  • zenius
    [REQUEST] Dell G3 3579 BIOS Password & AMI Protected Range/BIOS Guard Unlock
    by zenius
    Hello, I have an old Dell G3 3579 (ST: 2WQ7LP2-8FC8) with a newer 8FC8 BIOS password. I have successfully attached to the flash chip (W25Q128JVSQ) on the motherboard with a CH341A programmer and made several modifications using Intel FIT (e.g., allow software SPI write) without bricking. I was also able to boot to a modified GRUB shell where I attempted to edit many BIOS security related options like BIOS Guard/Lock, Flash Signature Override, ME FW Image Re-Flash, etc.

    Unfortunately, some of these modifications like to Intel BIOS Guard failed because it is fused into the PCH. Also,...
    12-08-2024, 06:13 AM
  • Wahaz
    Lenovo Thinkbook 15 G2 ITL i5 (serial number: MP2BFZEF) bios request
    by Wahaz
    Hello,

    I have a Lenovo Thinkbook 15 G2 ITL i5 Laptop (serial number: MP2BFZEF) that when I turn it on, the led on the power button lights up for 5 seconds, then goes out. There's no display and nothing happens.
    So I thought it was a Bios problem.
    I found 3 bios chips on the board, which I read with a bios programmer: two XMC model bios chips and a Winbond model bios chip. Each XMC model bios chip has two partitions named XM25QH128A [3.3V] and XT25F128A [3.3V]. And the Winbond model bios chip has three partitions named W25Q80BL 3.3V, W25Q80xV 3.3V and W25Q80DV 3.3V....
    10-30-2023, 08:42 PM
  • Bloodhoundje
    HP Pavilion Gaming Laptop 15-ec2523nd - Dimm2 slot disabled after corrupt bios repair? Advice requested.
    by Bloodhoundje
    Hi everyone,

    I have been doing hardware repair as a hobby for some years now and recently decided to learn about repairing laptops as a fun challenge.

    I managed to get my hands on a "HP Pavilion Gaming 15-ec2523nd" notebook that only shows a white power LED and doesnt respond to anything.

    After initial testing I concluded the bios seems to be corrupted since all voltages are normal and there are no shorts. HP has a feature for a bios restore from USB with winkey+B for this model. This did not work.

    I have desoldered the bios chip (GigaDevice...
    03-16-2024, 03:12 PM
  • Loading...
  • No more items.
Working...